header-logo
Suggest Exploit
vendor:
Web Protection Appliance
by:
Francisco Falcon, juan vazquez
N/A
CVSS
N/A
Command Injection
78
CWE
Product Name: Web Protection Appliance
Affected Version From: 3.7.0
Affected Version To: 3.7.0
Patch Exists: YES
Related CWE: CVE-2013-4984
CPE: a:sophos:web_protection_appliance
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux x86
2013

Sophos Web Protection Appliance clear_keys.pl Local Privilege Escalation

This module abuses a command injection on the clear_keys.pl perl script, installed with the Sophos Web Protection Appliance, to escalate privileges from the 'spiderman' user to 'root'. This module is useful for post exploitation of vulnerabilities on the Sophos Web Protection Appliance web ui, executed by the 'spiderman' user. This module has been tested successfully on Sophos Virtual Web Appliance 3.7.0.

Mitigation:

Update to the latest version of Sophos Web Protection Appliance
Source

Exploit-DB raw data: